PyDFIR / pyDFIRRam
PyDFIRRam is a Python library leveraging Volatility 3 to simplify and enhance memory forensics. It streamlines the research, parsing, and analysis of memory dumps, allowing users to focus on data rather than commands.
☆25Updated 7 months ago
Alternatives and similar repositories for pyDFIRRam:
Users that are interested in pyDFIRRam are comparing it to the libraries listed below
- ZeroProbe is an advanced enumeration and analysis framework designed for exploit developers, security researchers, and red teamers. It pr…☆103Updated 2 months ago
- Some of my Malware Analysis writeups.☆45Updated last year
- ☆67Updated 3 months ago
- ☆23Updated 2 months ago
- Shellcode loader based on indirect syscall☆22Updated 3 months ago
- Virus.xcheck is a Python tool designed to bulk verify the existence of file hashes in the Virus Exchange database and fetch download URLs…☆53Updated last month
- Free training course offered at Hack Space Con 2023☆138Updated 2 years ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆33Updated last week
- Configuration Extractors for Malware☆104Updated 2 weeks ago
- A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files☆124Updated 11 months ago
- Powershell Linter☆50Updated last week
- Modular framework for automating triaging, malware analysis, and analyst workflows☆36Updated last week
- APT hub, It help's research to collect information and data on the latest APT activities. It collects data on APT profiles, IOCs(1 yr), a…☆51Updated 2 months ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated 2 years ago
- ☆37Updated last year
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆160Updated last month
- Cheat sheet to detect and remove linux kernel rootkit☆58Updated 4 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆39Updated 3 months ago
- ☆85Updated 2 years ago
- DFIR project to collect and analyze events in Google Workspace☆12Updated last year
- A python script to automatically list vulnerable Windows ACEs/ACLs.☆53Updated 5 months ago
- A collection of tools that I use in CTF's or for assessments☆97Updated 3 months ago
- Repository of Yara Rules☆110Updated last month
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆149Updated 7 months ago
- linikatz is a tool to attack AD on UNIX☆146Updated last year
- ☆20Updated last year
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆16Updated 4 months ago
- Python tool to check rootkits in Windows kernel☆195Updated 2 months ago
- ☆39Updated 4 months ago
- ☆96Updated 2 weeks ago